CVE-2024-33507: Critical severity Fortinet FortiIsolator vulnerability
An insufficient session expiration vulnerability [CWE-613] and an incorrect authorization vulnerability [CWE-863] in FortiIsolator 2.4.0 through 2.4.4, 2.3 all versions, 2.2.0, 2.1 all versions, 2.0 all versions authentication mechanism may allow remote unauthenticated attacker to deauthenticate logged in admins via crafted cookie and remote authenticated read-only attacker to gain write privilege via crafted cookie.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33507?
CVE-2024-33507 is considered a high severity vulnerability due to its potential for unauthorized access and impact on session security.
How do I fix CVE-2024-33507?
To remediate CVE-2024-33507, users should upgrade FortiIsolator to the latest version that addresses this vulnerability.
What types of vulnerabilities does CVE-2024-33507 involve?
CVE-2024-33507 involves an insufficient session expiration vulnerability and an incorrect authorization vulnerability.
Who is affected by CVE-2024-33507?
CVE-2024-33507 affects FortiIsolator versions 2.4.0 through 2.4.4, along with all versions of 2.3, 2.2.0, 2.1, and 2.0.
Can CVE-2024-33507 be exploited remotely?
Yes, CVE-2024-33507 can be exploited by a remote unauthenticated attacker to deauthenticate users.